Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
1339 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.3) | 0.80% | — | Phoenixframework Phoenix | 7/7/2026 | 24/9/2026 | Improper Check for Unusual or Exceptional Conditions vulnerability in phoenixframework phoenix (Presence JavaScript client) allows an attacker with ordinary channel access to cause a persistent client-side denial of service against every viewer of a presence channel topic. This vulnerability is associated with program… | |
| Modificada | Alta (8.7) | 0.78% | — | Phoenixframework Phoenix | 7/7/2026 | 24/9/2026 | Allocation of Resources Without Limits or Throttling vulnerability in phoenixframework phoenix (Phoenix.Socket module) allows an unauthenticated attacker to cause a denial of service against any endpoint that mounts a Phoenix socket with a reachable channel transport (WebSocket or LongPoll). This vulnerability is… | |
| Aplazada | Alta (7.1) | 0.51% | — | Circl AIL FrameworkAI | 5/7/2026 | 6/7/2026 | AIL Framework contains a path traversal vulnerability in its PDF object handling. Prior to commit 14c618fce4d1df02358717c48ea903706abecdf2, the PDF.get_filepath() function constructed a file path by joining the configured PDF storage directory with a path derived from a PDF object identifier, without verifying that… | |
| Aplazada | Media (5.4) | 0.26% | — | Silverstripe CMSAISilverstripe FrameworkAI | 1/7/2026 | 2/7/2026 | Silverstripe Framework is a PHP framework which powers the Silverstripe CMS. In versions prior to 6.2.2, the "Insert media from web" functionality in the CMS is vulnerable to XSS from a specially crafted embed. This issue was fixed in version 6.2.2/ | |
| Aplazada | Media (4.8) | 0.40% | — | Frappe FrameworkAI | 24/6/2026 | 25/6/2026 | A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the frappe.ui.Tree component | |
| Aplazada | Media (4.6) | 0.43% | — | Frappe FrameworkAI | 24/6/2026 | 25/6/2026 | A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the Number Card component. | |
| Aplazada | Media (4.6) | 0.43% | — | Frappe FrameworkAI | 24/6/2026 | 25/6/2026 | A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to unsafe evaluation of user-controlled data in the Number Card component. | |
| Aplazada | Media (4.8) | 0.40% | — | Frappe FrameworkAI | 24/6/2026 | 25/6/2026 | A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the Notifications > Events panel. | |
| Aplazada | Media (4.8) | 0.40% | — | Frappe FrameworkAI | 24/6/2026 | 25/6/2026 | A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the MultiSelectDialog component. | |
| Aplazada | Media (4.6) | 0.43% | — | Frappe FrameworkAI | 24/6/2026 | 25/6/2026 | A Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of untrusted input in the Form Dashboard headline renderer. | |
| Aplazada | Media (4.6) | 0.43% | — | Frappe FrameworkAI | 24/6/2026 | 25/6/2026 | A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the File View breadcrumb renderer. | |
| Aplazada | Media (4.8) | 0.40% | — | Frappe FrameworkAI | 24/6/2026 | 25/6/2026 | A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the Desk desktop icon renderer. | |
| Aplazada | Media (5.1) | 0.45% | — | Frappe FrameworkAI | 24/6/2026 | 25/6/2026 | A Reflected Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the dashboard-view component. | |
| Aplazada | Media (4.6) | 0.43% | — | Frappe FrameworkAI | 24/6/2026 | 25/6/2026 | A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the frappe.get_avatar function. | |
| Aplazada | Media (4.6) | 0.53% | — | Frappe FrameworkAI | 24/6/2026 | 25/6/2026 | A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev. An authenticated attacker with write access to Auto Repeat can persist HTML/JavaScript in reference_document using a whitelisted write path and trigger script execution when users open the affected Auto Repeat form. | |
| Aplazada | Media (4.6) | 0.43% | — | Frappe FrameworkAI | 24/6/2026 | 25/6/2026 | A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input before generating HTML output in the Audit Trail component. | |
| Aplazada | Alta (8.3) | 0.44% | — | Circl AIL FrameworkAI | 22/6/2026 | 22/6/2026 | A path traversal vulnerability exists in AIL Framework before the release containing commit 0041456af25da0cdea1c1c4624e46baff2731d8f. An authenticated AIL user can supply crafted object identifiers through the investigation workflow to cause file paths to resolve outside the intended image, favicon, or screenshot… | |
| Aplazada | Media (5.3) | 0.51% | — | Circl AIL FrameworkAI | 19/6/2026 | 22/6/2026 | AIL framework contains a path traversal vulnerability in the /objects/item/diff endpoint. The endpoint accepts item identifiers through the s1 and s2 query parameters and, prior to the fix, attempted to retrieve and compare item contents without first verifying that both referenced items existed as valid AIL objects.… | |
| Analizada | Crítica (9.8) | 0.51% | — | Oracle Enterprise Command Center Framework | 17/6/2026 | 18/6/2026 | Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Core). Supported versions that are affected are V15 and V16. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Enterprise Command Center… | |
| Analizada | Crítica (9.9) | 0.39% | — | Oracle Enterprise Command Center Framework | 17/6/2026 | 18/6/2026 | Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Core). Supported versions that are affected are V15 and V16. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Enterprise Command Center… | |
| Analizada | Crítica (9.9) | 0.43% | — | Oracle Enterprise Command Center Framework | 17/6/2026 | 18/6/2026 | Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Core). Supported versions that are affected are V15 and V16. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Enterprise Command Center… | |
| Analizada | Crítica (9.6) | 0.36% | — | Oracle Enterprise Command Center Framework | 17/6/2026 | 18/6/2026 | Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Core). Supported versions that are affected are V15 and V16. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Enterprise Command Center… | |
| Analizada | Alta (8.1) | 0.38% | — | Oracle Enterprise Command Center Framework | 17/6/2026 | 18/6/2026 | Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Core). Supported versions that are affected are V15 and V16. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Enterprise Command Center… | |
| Analizada | Crítica (9.9) | 0.39% | — | Oracle Enterprise Command Center Framework | 17/6/2026 | 18/6/2026 | Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Core). Supported versions that are affected are V15 and V16. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Enterprise Command Center… | |
| Analizada | Crítica (9.1) | 0.49% | — | Oracle Enterprise Command Center Framework | 17/6/2026 | 18/6/2026 | Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Core). Supported versions that are affected are V15 and V16. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Enterprise Command Center… |